Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.8
Related:
Clause 5
|
5.2 Password authentication
|
SR 1.5 Authenticator management
|
2-1 Clause 11
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device
The lifecycle around passwords: generation, distribution, storage, rotation, recovery and revocation. Strength and process must match process criticality, not IT fashion.
Default passwords, sticky-note sharing, unmanaged resets, and stale credentials after staff or vendor changes.
Password policy on directories and local hosts; sealed envelopes or vaults for break-glass; vendor procedures for controller passwords. Cognitive or one-time methods appear where the TR called for stronger practice on high-value systems.
Emergency access fights unique passwords. Shared console accounts fight accountability. Rotation that is too aggressive drives workarounds. Rotation that never happens leaves defaults in place.
Small, isolated, low-value systems that are not internet-connected can use simple passwords. Interconnected systems that hold valuable information or control valuable or hazardous processes need managed, stronger password security.